Ask Runable forDesign-Driven General AI AgentTry Runable For Free
Runable
Back to Blog
Technology6 min read

Employees thought they were fixing a browser error until fake IT support quietly walked them through infecting their own company computers | TechRadar

A simple spam flood and fake support call is enough to plant Havoc malware Discover insights about employees thought they were fixing a browser error until fake

TechnologyInnovationBest PracticesGuideTutorial
Employees thought they were fixing a browser error until fake IT support quietly walked them through infecting their own company computers | TechRadar
Listen to Article
0:00
0:00
0:00

Employees thought they were fixing a browser error until fake IT support quietly walked them through infecting their own company computers | Tech Radar

Overview

'What begins as a phone call from 'IT support' ends with a fully instrumented network compromise': This fake tech support scam tricks employees into infecting their own company devices

A simple spam flood and fake support call is enough to plant Havoc malware

Details

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Attackers now rely on employees to unknowingly launch the malware themselves

Fake IT support calls transform routine troubleshooting into a full network compromise

Browser crashes become the opening move in carefully staged social engineering attacks

Cybercriminal activity continues to move away from direct software exploitation toward manipulating everyday user behavior within corporate environments, experts have warned.

New research by Huntress describes a campaign in which attackers intentionally crash a user’s browser and display alarming security messages that encourage a “repair.”

The tactic creates a false sense of urgency while allowing the attacker to initiate direct communication with the employee.

The silent DNS malware that’s redefining email and web-based cyberattacks

This phishing campaign spoofs internal messages - here's what we know

Watch out - hackers are coming after your Christmas bonus, as paychecks come under threat

In many observed cases, victims received phone calls from individuals claiming to be internal technical staff responsible for resolving the issue, giving the attacker credibility and creates pressure for the employee to cooperate with instructions that appear routine.

The entire chain begins with spam messages flooding a user’s mailbox. Soon after, a phone call arrives from someone claiming to represent “IT support”, who says the spam or browser malfunction requires immediate maintenance on the affected computer.

The deception works because victims are persuaded to perform the actions that trigger the compromise themselves.

Researchers explained that the attackers rely on manual user interaction rather than automated malware delivery, as victims are guided through steps such as approving remote access sessions or installing remote administration tools like Any Desk.

In other cases, users are instructed to copy and paste commands into system prompts or execute scripts disguised as diagnostic fixes.

The attackers open a browser during remote sessions and direct victims to a fraudulent Microsoft-themed interface hosted on cloud infrastructure.

Who's watching who? Experts reveal criminals using fake enterprise software to gain access to company systems

These fake Chrome extensions will crash your browser so that hackers can sneak in - here's how to stay safe

Watch out: hackers are hijacking Microsoft Teams messages to try and get access to your emails - here's what you need to look out for

Once the so-called repair files were executed, the malicious chain reconstructed itself locally using a staged payload, unpacking files that appeared to resemble legitimate software components, including runtime libraries and executable utilities.

One binary named ADNotification Manager.exe triggers the next phase of the compromise after installation.

At this stage, attackers rely heavily on a technique known as DLL sideloading to run malicious code while legitimate applications continue operating normally.

Malicious dynamic libraries were placed beside legitimate files, allowing the malware to run without immediately triggering obvious alarms within the system.

The payload ultimately deployed a modified agent derived from the open-source command-and-control framework Havoc C2.

And “what once ended with a $300 gift card purchase now ends with a modified Havoc C2 framework burrowed into your environment.”

The activity is swift, in one case, the intruder expanded from the initial compromised computer to nine additional endpoints within roughly eleven hours.

Such rapid activity indicates direct operator control rather than automated malware spreading through vulnerabilities.

The attacker used remote management tools and scripted payloads to maintain persistence while moving through connected systems.

The researchers warn that the campaign reiterates how attackers increasingly depend on social interaction rather than technical flaws to bypass firewall defenses.

Follow Tech Radar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow Tech Radar on Tik Tok for news, reviews, unboxings in video form, and get regular updates from us on Whats App too.

Efosa has been writing about technology for over 7 years, initially driven by curiosity but now fueled by a strong passion for the field. He holds both a Master's and a Ph D in sciences, which provided him with a solid foundation in analytical thinking.

You must confirm your public display name before commenting

1 Amazon's cheap 4K streaming stick drops to under $20 for the first time

2 Compal's latest laptop concept adds a color E-Ink display that piques my curiosity — but I am not sure it will turn into a real product because of one flaw

3'Everybody talks about what's the next AI device... Glasses, obviously is one of them' — Samsung exec teases details about its forthcoming XR glasses, and when they might arrive

4I haven’t sat in a plusher gaming chair than this one – but this affordable GTPlayer model has one drawback

5I've hunted out the best Galaxy S26 cases to keep your swanky new phone protected

Tech Radar is part of Future US Inc, an international media group and leading digital publisher. Visit our corporate site.

© Future US, Inc. Full 7th Floor, 130 West 42nd Street, New York, NY 10036.

Key Takeaways

  • 'What begins as a phone call from 'IT support' ends with a fully instrumented network compromise': This fake tech support scam tricks employees into infecting their own company devices

  • A simple spam flood and fake support call is enough to plant Havoc malware

  • When you purchase through links on our site, we may earn an affiliate commission

  • Attackers now rely on employees to unknowingly launch the malware themselves

  • Fake IT support calls transform routine troubleshooting into a full network compromise

Cut Costs with Runable

Cost savings are based on average monthly price per user for each app.

Which apps do you use?

Apps to replace

ChatGPTChatGPT
$20 / month
LovableLovable
$25 / month
Gamma AIGamma AI
$25 / month
HiggsFieldHiggsField
$49 / month
Leonardo AILeonardo AI
$12 / month
TOTAL$131 / month

Runable price = $9 / month

Saves $122 / month

Runable can save upto $1464 per year compared to the non-enterprise price of your apps.